Skip to content
GoalCoder
Workflow Requirements Pricing Support

Privacy · Last updated 6 August 2026

Privacy notice

This notice explains how GoalCoder handles information for the public website, support, subscriptions, account security, licensing, and application delivery.

Controller and contact

Jacek Musial trading as GoalCoder
UK sole trader
66 Paul Street, London, EC2A 4NA, United Kingdom

Email support@goalcoder.com for a privacy question or to exercise a data right.

Public website delivery

The public website uses no behavioral analytics, advertising or marketing pixels, session replay, heatmaps, browser fingerprinting, cross-site tracking, analytics cookies, or persistent visitor identifiers. It does not collect marketing email addresses.

Website delivery and security can expose minimum transport information such as IP address, timestamp, requested path, response status, and user agent to the hosting and security providers. GoalCoder does not join that information to account, billing, activation, or licensing records to build visitor profiles.

Account, subscription, and licensing operations

When you request an account, subscription, activation, support, closure, or data-rights operation, GoalCoder may process your email address, purchase-operation identifiers, Stripe/Link customer and subscription linkage, compact entitlement state, activation public keys and device records, security and rate-limit facts, account-security email outcomes, operator-audit facts, and support correspondence.

GoalCoder does not receive or store full payment-card numbers or CVC. It does not store provider credentials. You provide account and support information directly; Stripe/Link and Mailgun provide the minimum transaction and delivery facts needed for the requested operation.

Purposes and lawful bases

  • Contract and steps you request before a contract: account verification, subscription setup, licensing, activation, delivery, updates, cancellation, closure, and requested product support.
  • Legitimate interests: proportionate service security, abuse prevention, reliable delivery, reconciliation, audit, and defence of legal claims. GoalCoder balances those interests against your rights and does not use them for behavioral advertising.
  • Legal obligations: accounting, tax, consumer, dispute, fraud, sanctions, and data-rights records where the law requires them.
  • Consent: only for a specific optional action where consent is the appropriate legal basis. You may withdraw that consent without affecting earlier lawful processing.

Repository, run, and provider data

GoalCoder does not transmit ordinary repository and run content through normal product operation. Requests, paths, diffs, run artifacts, logs, answers, and provider output stay on your Mac unless you deliberately choose to send selected material to support.

Codex and Claude Code process the repository context, prompts, tool results, and model output needed for a run under the provider you choose, its terms, and its account settings. Repository tools can also use their own network services. That provider and task-driven processing is separate from GoalCoder's first-party account and licensing processing.

Processors and international transfers

GoalCoder uses DigitalOcean for public website hosting, GoDaddy for registrar and DNS, and Fastmail for support email. When account, subscription, licensing, delivery, backup, or protected release operations are offered and requested, GoalCoder may use DigitalOcean App Platform, Managed PostgreSQL, and Spaces for the deployed product, Cloudflare R2 for locked backup and release copies, Stripe/Link for commerce and transaction support, Mailgun EU for account-security email, GitHub for source hosting and pull-request records, and Apple for Developer ID signing and notarization.

These providers may use affiliates or infrastructure outside the United Kingdom. Where GoalCoder initiates a restricted transfer, it relies on applicable UK adequacy regulations or appropriate contractual safeguards and completes any required transfer assessment. Contact support for information about the safeguard used for a specific transfer.

Retention

GoalCoder has accepted the following policy targets for account, subscription, licensing, delivery, and related support processing. Each period becomes an operational commitment only when the corresponding service is enabled and its retention controls are deployed and verified. Until then, these periods are policy targets, not current operational guarantees.

  • Policy target: one-time grants, activation challenges, browser operation state, and fallback results: within 24 hours after use or expiry.
  • Policy target: terminal purchase and Checkout-operation state: 30 days unless needed to reconcile an account or dispute.
  • Policy target: minimum Stripe event and reconciliation outcomes: 90 days.
  • Policy target: mail-delivery outcomes: 30 days; account-security notifications and operator security-action evidence: 12 months.
  • Policy target: normalized email and source-IP rate-limit material: no more than 24 hours. Product tables do not retain raw source IP addresses.
  • Policy target: inactive minimum account and prior-trial facts: 24 months after the last account or billing activity unless closure or a documented hold applies.
  • Policy target: support correspondence: 12 months after resolution, or longer for an active dispute or legal hold.
  • Policy target: accounting, tax, payout, invoice, and refund records: for the period required by applicable law.

Policy target: an accepted account-closure request deletes or anonymizes product data within 30 days after subscription cancellation is confirmed, subject to a documented legal, accounting, dispute, fraud, or security hold. Encrypted backups expire under their separate rotation and are not used to restore a closed account to ordinary operation.

Strictly necessary technologies

Public content pages set no application cookie or browser-storage value. User-requested authentication, Checkout, billing management, fraud prevention, or security operations may use short-lived storage that is strictly necessary to complete and protect that operation. GoalCoder does not use a consent banner to introduce nonessential tracking.

Automated account decisions

GoalCoder automatically projects verified billing facts into trial, paid, payment-recovery, or inactive access. This controls whether a new run can start; it is not behavioral profiling. Email support if you believe an account or entitlement state is wrong and want it reviewed.

Your rights and complaints

Depending on applicable law and the purpose of processing, you may have rights to access, correct, erase, restrict, object to, or receive your information, and to withdraw consent. Some rights are not absolute where GoalCoder must keep information for a contract, legal obligation, dispute, fraud, or security purpose.

You may complain to the UK Information Commissioner's Office at ico.org.uk. Contacting GoalCoder first is welcome but is not required. Account closure does not delete local runs, workspaces, or artifacts from your Macs.

Security and changes

GoalCoder separates the public site, account service, worker, provider credentials, and local run data, and limits each component to the information it needs. No system can be guaranteed risk-free. GoalCoder updates this notice when its processing, providers, retention, or legal obligations materially change and records the effective date above.

GoalCoder

Disciplined agent work for existing repositories.

Privacy Terms Support
@goalcoder on X @nanomader on X